Skip to content

docs: disclose Google CLI privacy practices - #35

Merged
rianjs merged 2 commits into
mainfrom
docs/google-cli-privacy
Sep 28, 2026
Merged

rianjs merged 2 commits into
mainfrom
docs/google-cli-privacy

Conversation

@rianjs

@rianjs rianjs commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Adds a prominent unofficial Google relationship statement and links the shared privacy policy from the README. Adds PrivacyUrl and clearly unofficial descriptions to both Winget locale templates. No CLI or release behavior changes.

@rianjs

rianjs commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Blocker

  • README.md:3, packaging/winget/OpenCLICollective.google-readonly.locale.en-US.yaml:12, and packaging/winget/OpenCLICollective.google-readwrite.locale.en-US.yaml:12 point to the main privacy-policy URL, but its current public content has no Google CLI section and retains the generic no-storage statement. The product-applicable section exists only in unmerged open-cli-collective/.github PR #50. The URL resolves, but it does not meet the approved plan's public, applicable-policy requirement. Publish that policy before the manifests are reviewed.

Major

  • The changed contract fields at packaging/winget/OpenCLICollective.google-readonly.locale.en-US.yaml:12-15 and packaging/winget/OpenCLICollective.google-readwrite.locale.en-US.yaml:12-15 have no premerge assertion. identity-check verifies identifiers, while the shared renderer test at /Users/rianjs/dev/.github/actions/winget-submit/test_winget_submit.py:357-364 checks only version and manifest schema values. Current CI can therefore pass with a different valid PrivacyUrl or an omitted/changed unofficial attribution. Add one small check that parses both locale templates, asserts the canonical URL and attribution, and renders the bootstrap manifest before checking those same rendered values.

@rianjs-bot rianjs-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated PR Review

Reviewed commit: 47f7e9affdda
Profile: codex-rianjs-bot - Posting as: rianjs-bot[bot]

Summary

Reviewer Findings
documentation:docs 0
policies:conventions 1
automation:ci-release 0
policies:conventions (1 finding)

Blocking - README.md:3

The README and both WinGet manifests link to the public main-branch privacy policy, but that policy has no Google CLI section and says projects do not intentionally store personal information. That conflicts with the README’s promise that the link explains Google account data and local storage practices. Publish the Google CLI section in the shared policy before merging these links, or link to an accurate published policy.

Reviewer Coverage

  • documentation:docs — complete (broad); skipped: none; constraints: Review limited to the three assigned documentation and Winget locale files.
  • policies:conventions — complete (broad); skipped: none; constraints: Review limited to the three assigned changed files and the publicly linked privacy policy.
  • automation:ci-release — complete (broad); inspected 2 assigned files (3 inspected across reviewers): packaging/winget/OpenCLICollective.google-readonly.locale.en-US.yaml, packaging/winget/OpenCLICollective.google-readwrite.locale.en-US.yaml; skipped: none; constraints: Review limited to the two assigned WinGet locale templates and their distribution metadata.
Inspected files (3)
  • README.md
  • packaging/winget/OpenCLICollective.google-readonly.locale.en-US.yaml
  • packaging/winget/OpenCLICollective.google-readwrite.locale.en-US.yaml

0 PR discussion threads considered. 0 summarized; 0 resolved.


Completed in 1m 09s | gpt-6-sol | cr 0.10.314
Field Value
Model gpt-6-sol
Reviewers documentation:docs, policies:conventions, automation:ci-release
Engine codex_cli · gpt-6-sol
Reviewed by cr · rianjs-bot[bot]
Duration 1m 09s wall · 1m 33s compute
Cost unavailable
Tokens 266.8k in / 2.9k out

Per-workstream usage

  • orchestrator-selection — gpt-6-sol
    • In: 16.7k
    • Out: 401
    • Cache read: 11.8k
    • Cache create: unavailable
    • Cost: unavailable
    • Duration: 13s
  • documentation:docs — gpt-6-sol
    • In: 88.9k
    • Out: 803
    • Cache read: 59.4k
    • Cache create: unavailable
    • Cost: unavailable
    • Duration: 29s
  • policies:conventions — gpt-6-sol
    • In: 61.3k
    • Out: 423
    • Cache read: 49.4k
    • Cache create: unavailable
    • Cost: unavailable
    • Duration: 17s
  • automation:ci-release — gpt-6-sol
    • In: 64.1k
    • Out: 718
    • Cache read: 50.9k
    • Cache create: unavailable
    • Cost: unavailable
    • Duration: 26s
  • orchestrator-rollup — gpt-6-sol
    • In: 35.8k
    • Out: 586
    • Cache read: 28.3k
    • Cache create: unavailable
    • Cost: unavailable
    • Duration: 7s

Comment thread README.md
@@ -1,5 +1,7 @@
# Google CLI

> **Unofficial:** `gro` and `grw` are independent open-source tools and are not affiliated with, sponsored by, or endorsed by Google. See the [Open CLI Collective Privacy Policy](https://github.com/open-cli-collective/.github/blob/main/privacy-policy.md) for their Google account data and local storage practices.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The README and both WinGet manifests link to the public main-branch privacy policy, but that policy has no Google CLI section and says projects do not intentionally store personal information. That conflicts with the README’s promise that the link explains Google account data and local storage practices. Publish the Google CLI section in the shared policy before merging these links, or link to an accurate published policy.

Reply inline to this comment.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by merging Open CLI Collective policy PR #50 as b47a22eccc754837d1a9344cb4a5536057033ba0. The public policy at https://github.com/open-cli-collective/.github/blob/main/privacy-policy.md now includes the Google CLI section, local storage details, and OAuth revocation instructions; an anonymous fetch of the main page returns HTTP 200 and exposes those sections.

@rianjs

rianjs commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Approval override requested: the sole review finding is resolved. Shared policy PR #50 is merged as b47a22eccc754837d1a9344cb4a5536057033ba0, and the public policy at https://github.com/open-cli-collective/.github/blob/main/privacy-policy.md now contains the Google CLI account-data, local-storage, and revocation details linked by this PR. Please approve this PR without another code change.

@rianjs-bot rianjs-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving after an explicit PR author override request following a prior codereview pass.

@rianjs
rianjs merged commit 733a298 into main Sep 28, 2026
11 checks passed
@rianjs
rianjs deleted the docs/google-cli-privacy branch September 28, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant